Scope chapter quiz
Scope chapter quiz
Pick the answer that best matches the methodology.
A confirmed compromise of a system processing payment card data is detected. The technical investigation will take days. What does Scope require the analyst to do about timing?
PCI breach-notification timelines run independently of the technical investigation. Scope is the phase where regulatory obligations are recognized, and engaging compliance early lets those clocks run in parallel with technical work rather than serially after.
An alert looks like phishing-driven intrusion. What is the typical historical window for the investigation?
Phishing-driven intrusion typically progresses within days, but ruling out earlier staging requires a longer look on the primary entities. The two-window pattern (short primary + extended look on primaries) is a common Scope decision for this threat type.
An alert on a build-pipeline service account smells like possible supply-chain compromise. What historical window does Scope set?
The window follows the threat type, not a default. Supply-chain compromises often predate their first alert by weeks or months: the malicious component may have shipped in an update long since deployed. The 1-to-6-month window is bounded by what the SOC actually retains, and if retention falls short, the gap is documented in the Scope output rather than ignored.
The Subject phase identified seven identities connected to the alert. How many should be primary in scope?
Primary entities are those directly involved in the alert. Secondary entities are connected but not in the alert. The split keeps investigation depth proportional to evidence rather than spending equal time on every identity in the map.
Alert and Subject both lean benign on a developer-workstation alert, but the user's account can reach a dozen other systems. How does Scope draw the boundary?
This is restraint scoping, and it is as much a Scope skill as expansion. Access alone is topology, not evidence, and every entity added spends Uncover's depth where there is no signal. The narrow boundary is defensible precisely because the expansion path exists: if Uncover surfaces evidence touching another system, the decision tree grows the boundary with a documented justification. Sprawl on a benign-leaning case is how a fast close becomes a five-hour one.
An investigation needs in-app activity from a SaaS platform, but the SOC only has authentication logs and gross API metrics. What does Scope require?
Naming what cannot be seen is part of Scope. It prevents wasted effort on impossible queries, and it lets the analyst submit vendor or external-team requests early so the data arrives in parallel.
A hospital SOC confirms a compromised workstation had access to systems holding PHI. When does HIPAA's 60-day individual-notification clock start?
The 60-day clock (45 CFR §164.404) runs from discovery, not from confirmation; discovery is a knew-or-should-have-known standard applied to the whole workforce. The alert that starts triage can be the discovery event, which is why Scope commits the timestamp and engages the privacy officer early. The four-factor assessment (§164.402) decides whether notification is required at all; it does not pause the clock.
During Scope, the analyst confirms that a compromised account assumed a cloud role during the investigation window. The decision-tree response is...
The IF/THEN decision-tree pattern is Scope's structured way of evolving the boundary. A cloud-role assumption is evidence; the methodology says incorporate it now and document the three-line justification (evidence, risk, required actions) so the expansion is defensible. Waiting for Uncover to surface it would mean Uncover queries outside its own scope to find what Scope should have already framed.
Scope confirms a compromised identity can reach systems inside the cardholder data environment (CDE). What does the methodology require?
PCI DSS is contractual: card-brand rules require prompt notification of suspected account-data compromise through the acquirer, and a PFI may later re-examine everything preserved in the first hours. A compliant environment guarantees 12 months of audit logs with 3 months immediately available (Req. 10.5.1), but stopping rotation is still the analyst's job. And investigative access into the CDE follows the same least-privilege controls as any other access: defaulting to full access is exactly backwards.
A US SOC investigates a compromised account belonging to an employee in Germany, with the relevant logs stored in an EU region. What does Scope's sovereignty boundary require?
Data-residency rules can prevent moving log data across regions, and employee-privacy regimes can restrict what is examined at all. Scope is where that constraint is recognized, because discovering it mid-Uncover means evidence already moved where it should not have. The pseudonymization distractor fails for a reason worth knowing: data that can be re-linked to a person generally remains personal data under GDPR, so stripping usernames does not lift the constraint.
The Scope handoff to Uncover should include investigative questions. Why?
Need a nudge?
Think about what makes the difference between focused triage and unstructured exploration.
Uncover's depth comes from working through specific investigative questions. How did the attacker get in? What systems were touched? Was data moved? Is persistence active? Scope frames those questions before the data is pulled, which is what keeps Uncover from running broad queries and hoping. The questions are how the methodology converts a boundary into actionable analytical effort.